Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

App Control: Agents Remain Disconnected After Recent Certificate Expiration and Renewal

App Control: Agents Remain Disconnected After Recent Certificate Expiration and Renewal

Environment

  • App Control Server: 8.9.4+
  • App Control Agent: All Supported Versions

Symptoms

  • Agent Server Communication Certificate expired, causing all Agents to become disconnected.
  • Communication Certificate was replaced, but Agents remain in a disconnected state.

Cause

By default the Server will prioritize the previous Communication Certificate for 60 minutes after it is replaced. In the event this certificate was expired, this prioritization will cause the Agents to remain in a disconnected state.

Resolution

  1. Log in to the Console and navigate to https://ServerAddress/shepherd_config.php
  2. Select the Property CertificateDelaySwapMinutes and change the Value to 0
  3. Restart the App Control Server service.
  4. Verify the Agents are once again showing as Connected.
  5. Return the Property CertificateDelaySwapMinutes to the default Value of 60

Additional Notes

  • These steps are not necessary if the Communication Certificate is/was replaced prior to expiration.
  • This setting is meant as a way to allow both the old and new Communication Certificates to be accepted.
  • This is currently being investigated by Engineering (EP-19021) and will be addressed in a future update.

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎07-10-2023
Views:
446
Contributors